Impact
The rtl2832_sdr kernel driver for Linux audio devices contains a resource leak: on USB disconnect, the driver clears the device reference before releasing DMA buffers and URBs, causing usb_free_coherent to silently drop the buffers when a NULL argument is passed. The leaked coherent DMA buffers and URBs accumulate, leading to incremental memory consumption and potential exhaustion, but do not provide an attacker with direct control or privilege escalation.
Affected Systems
Any Linux kernel that includes the rtl2832_sdr media driver before the applied patch is affected. The specific kernel versions are not enumerated in the available data, but the vulnerability was fixed in a recent kernel revision after commit 034b6a4f9.
Risk and Exploitability
The EPSS score is below 1 %, indicating a very low probability of exploitation in production environments, and the vulnerability is not listed in CISA’s KEV catalog. While the CVSS score is not provided, the impact is limited to resource exhaustion. An attacker would need local access to control USB disconnects and active streaming, making realistic exploitation unlikely. The overall risk is thus low but non‑negligible for systems that frequently plug and unplug SDR devices.
OpenCVE Enrichment
Debian DLA
Debian DSA